5 ms·
is this still relevant? the article is 2 years old, was the flaw addressed?
by rjblackman 4y ago
is this still relevant? the article is 2 years old, was the flaw addressed?
- shakna 4y agoNot only was the flaw unaddressed, the decision was made to make it harder to see who is requesting the code - the app now only shows the user an accept/reject button. The replay attack can be done entirely passively, without any awareness that it has taken place, even by a user who is paying attention.